Subscribe via feed.
Archive for July, 2020

Online Polling System SQL Injection

Posted by deepcore under exploit (No Respond)

Online Polling System from sourcecodester.com suffers from a remote SQL injection vulnerability that allows for authentication bypass.

User Registration And Login And User Management System 2.1 SQL Injection

Posted by deepcore under exploit (No Respond)

User Registration and Login and User Management System with admin panel version 2.1 suffers from multiple remote SQL injection vulnerabilities. One allows for authentication bypass.

Small CRM 2.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Small CRM version 2.0 suffers from a remote SQL injection vulnerability. This version was first discovered to have a different SQL injection vulnerability in January of 2020 by FULLSHADE.

Curfew e-Pass Management System 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Curfew e-Pass Management System version 1.0 suffers from a remote SQL injection vulnerability.

Online Birth Certificate System 1.0 SQL Injection / Code Execution

Posted by deepcore under exploit (No Respond)

Online Birth Certificate System version 1.0 suffers from a remote SQL injection vulnerability that allows for remote code execution.

[webapps] Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 – Remote Code Execution (Metasploit)

Posted by deepcore under Security (No Respond)

Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 – Remote Code Execution (Metasploit)

Tags: ,

[webapps] BSA Radar 1.6.7234.24750 – Local File Inclusion

Posted by deepcore under Security (No Respond)

BSA Radar 1.6.7234.24750 – Local File Inclusion

Tags: ,

Responsive Online Blog 1.0 SQL Injection

Posted by deepcore under exploit (No Respond)

Responsive Online Blog version 1.0 remote SQL injection proof of concept exploit. Original discovery of the vulnerability is attributed to Eren Simsek.

Liferay Portal Remote Code Execution

Posted by deepcore under exploit (No Respond)

Liferay Portal versions prior to 7.2.1 CE GA2 exploit that gains code execution due to deserialization of untrusted data sent to the JSON web services interface.

Online DJ Booking Management System Project Report 1.0 SQL Injection / Code Execution

Posted by deepcore under exploit (No Respond)

Online DJ Booking Management System Project Report version 1.0 remote SQL injection exploit that achieves code execution.